13 Commits
Author SHA1 Message Date
SquidSec Bot ee0af7d76b ci: pin SquidGate action ref to v1.0.0-build.4 in release workflow v1.0.0 v1.0 v1 v1.0.0-build.6 2026-08-03 11:31:34 -04:00
SquidSec Bot 7a6065829b ci: pin SquidGate@v1.0.0-build.4 and use self-hosted runners
Standardize org workflows on SquidSec self-hosted runners and the
latest SquidGate release. Restrict PR jobs to same-repo heads so
fork code never runs on self-hosted.
v1.0.0-build.5
2026-08-03 11:29:56 -04:00
☣️ Mr. The Plague ☣️ 5424e7343a Merge pull request #22 from SquidSec/fix/code-review-hardening
fix: harden diff path, LLM retries, and category filtering
v1.0.0-build.4
2026-07-29 06:52:03 -05:00
Mr. The Plague 1a7f3180df fix: harden diff path, LLM retries, and category filtering
Address code-review gaps for v1: API-first PR diffs with merge-base
git fallback, exponential backoff on LLM 429/5xx, balanced JSON
extraction with parse_error surfacing, real policy.categories
post-filter, few-shot prompts, and correct block_on: none semantics.
2026-07-29 07:48:22 -04:00
SquidSec Bot 13a695223f chore: polish action.yml for GitHub Marketplace listing
- Clearer description and input order for marketplace UI
- branding: shield / red (required for Marketplace)
- Draft release notes for v1.0.0 Marketplace publish
v1.0.0-build.3
2026-07-28 16:21:24 -04:00
☣️ Mr. The Plague ☣️andSquidSec Bot 31bd057301 test
Demo only — hardcoded secret + injection / dangerous API patterns.
See examples/README.md

Co-authored-by: SquidSec Bot <bot@squidsec.local>
2026-07-28 16:18:17 -04:00
SquidSec Bot 938fdf1b1d fix: release badges, branch protection docs, drop unrelated links
- Fix shields.io release badge (include_prereleases + sort=date)
- Document required SquidGate checks for merge blocking
- Remove BloodBash/SquidScanner references
- Repo is public; main protected by ruleset requiring SquidGate
v1.0.0-build.2
2026-07-28 16:17:59 -04:00
SquidSec Bot c4b42d810d docs: SquidSec branding (BloodBash style) + release tags
- Centered SquidSec logo and About section matching BloodBash
- Badges: CI, Build and Release, latest release, MIT
- Release workflow: v1.0.0-build.N + floating v1 / v1.0 / v1.0.0
- assets/squidsec-logo.png from SquidSec brand kit
- Version/tag consumer docs; homepage squidoffense.com
v1.0.0-build.1
2026-07-28 16:12:05 -04:00
SquidSec Bot ee7d42ee22 docs: add language sample gallery (20 languages) 2026-07-28 16:07:24 -04:00
SquidSec Bot a0082ac8f1 release: rebrand as SquidGate and prepare for open source
- Product name SquidGate (check run, action, package, docs)
- Config path .github/squidgate.yml
- MIT © SquidSec; production README and docs
- CONTRIBUTING, SECURITY, CHANGELOG
- CI verifies dist/ is current
2026-07-28 16:06:15 -04:00
SquidSec Bot 9776fbcfbe chore: activate security-scan with xAI Grok (grok-build-0.1) using provided key via secret 2026-07-28 15:57:48 -04:00
SquidSec Bot e956f5bc43 ci: add test workflow (users can switch to self-hosted runners) 2026-07-28 15:54:33 -04:00
SquidSec Bot 26635182de feat: initial security-scan GitHub Action with full unit tests
- Refactored into testable modules (config, prompts, llm, checks)
- Comprehensive unit tests for config loading/merging/overrides,
  severity blocking, prompt construction (OWASP/CWE enforcement),
  LLM JSON extraction (noisy output handling),
  check run annotations, PR comments, filtering
- All claims from spec validated (21 tests)
- Dist bundle included for action consumption
- Private repo under SquidSec for self-hosted runner support
2026-07-28 15:54:21 -04:00